2023 CVE Vulnerabilities

31,244 CVEs published in 2023.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2023-38894CRITICAL9.8A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code vi...
CVE-2023-20017CRITICAL9.1Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to ...
CVE-2023-20013CRITICAL9.1Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to ...
CVE-2023-4204CRITICAL9.8NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses...
CVE-2023-39115CRITICAL9.8install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum...
CVE-2023-33663CRITICAL9.8In the module “Customization fields fee for your store” (aicustomfee) from ai-dev module for PrestaShop, an attacker can...
CVE-2023-32493CRITICAL9.8 Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker ...
CVE-2023-39851CRITICAL9.8webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE:...
CVE-2023-39850CRITICAL9.8Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parame...
CVE-2023-39852CRITICAL9.8Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NO...
CVE-2023-38866CRITICAL9.8COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST re...
CVE-2023-38864CRITICAL9.8An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter...
CVE-2023-4344CRITICAL9.8Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup ...
CVE-2023-4342CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security ...
CVE-2023-4341CRITICAL9.8Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI
CVE-2023-4340CRITICAL9.8Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file
CVE-2023-4338CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide...
CVE-2023-4337CRITICAL9.8Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installa...
CVE-2023-4336CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua...
CVE-2023-4329CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safegua...
CVE-2023-4325CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities
CVE-2023-4324CRITICAL9.8Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy h...
CVE-2023-4323CRITICAL9.8Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup
CVE-2023-38865CRITICAL9.8COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST re...
CVE-2023-38863CRITICAL9.8An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in th...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now